<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Maestro Security Group Management Interfaces in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Security-Group-Management-Interfaces/m-p/142213#M816</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Im going through a replacement of a Cluster of Gateways split across 2 sites with a pair Maestros and 4x 7000 clusters split across 2 sites&lt;BR /&gt;&lt;BR /&gt;Simply put the original site Gateway has multiple Interfaces, and the important part is that they use the Mgmt interface and route to and from it.&amp;nbsp; Assume its IP is 192.168.101.1/24&lt;/P&gt;&lt;P&gt;The SMS is 192.178.101.100&lt;/P&gt;&lt;P&gt;So the SMS can get to the internet via 192.168.101.1, as the GW is its default gateway.&lt;/P&gt;&lt;P&gt;the 192.168.101.0/24 network only has one router on it, the GW&amp;nbsp;@ .1 and has several other devices that are required on it, including things like LoM and similar.&lt;/P&gt;&lt;P&gt;So, onto my question&lt;/P&gt;&lt;P&gt;Im getting confused with the Maestro Management Interfaces - Ports 1-4 on the MHO 140&lt;BR /&gt;&lt;BR /&gt;I know that they are used for the Security Groups. When I set up a security group to replace the original Gateway, Im going to need it to have access and be managed via 192.168.101.0/24. But Im also going to need it to continue routing to and from that network.&lt;BR /&gt;&lt;BR /&gt;How do I go about setting this up, will that Ports 1-4 route the traffic? are there any gotchas I need to know about?&lt;BR /&gt;&lt;BR /&gt;Im guessing that this is a common replacement but the way that ports 1-4 are labled has got me worried&lt;/P&gt;&lt;P&gt;Oh and Im running R81.10 SP with hotfix Take 30&lt;/P&gt;&lt;P&gt;Thanks in advance&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 22 Feb 2022 17:13:34 GMT</pubDate>
    <dc:creator>Gingerwerewolf</dc:creator>
    <dc:date>2022-02-22T17:13:34Z</dc:date>
    <item>
      <title>Maestro Security Group Management Interfaces</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Security-Group-Management-Interfaces/m-p/142213#M816</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Im going through a replacement of a Cluster of Gateways split across 2 sites with a pair Maestros and 4x 7000 clusters split across 2 sites&lt;BR /&gt;&lt;BR /&gt;Simply put the original site Gateway has multiple Interfaces, and the important part is that they use the Mgmt interface and route to and from it.&amp;nbsp; Assume its IP is 192.168.101.1/24&lt;/P&gt;&lt;P&gt;The SMS is 192.178.101.100&lt;/P&gt;&lt;P&gt;So the SMS can get to the internet via 192.168.101.1, as the GW is its default gateway.&lt;/P&gt;&lt;P&gt;the 192.168.101.0/24 network only has one router on it, the GW&amp;nbsp;@ .1 and has several other devices that are required on it, including things like LoM and similar.&lt;/P&gt;&lt;P&gt;So, onto my question&lt;/P&gt;&lt;P&gt;Im getting confused with the Maestro Management Interfaces - Ports 1-4 on the MHO 140&lt;BR /&gt;&lt;BR /&gt;I know that they are used for the Security Groups. When I set up a security group to replace the original Gateway, Im going to need it to have access and be managed via 192.168.101.0/24. But Im also going to need it to continue routing to and from that network.&lt;BR /&gt;&lt;BR /&gt;How do I go about setting this up, will that Ports 1-4 route the traffic? are there any gotchas I need to know about?&lt;BR /&gt;&lt;BR /&gt;Im guessing that this is a common replacement but the way that ports 1-4 are labled has got me worried&lt;/P&gt;&lt;P&gt;Oh and Im running R81.10 SP with hotfix Take 30&lt;/P&gt;&lt;P&gt;Thanks in advance&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Feb 2022 17:13:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Security-Group-Management-Interfaces/m-p/142213#M816</guid>
      <dc:creator>Gingerwerewolf</dc:creator>
      <dc:date>2022-02-22T17:13:34Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Security Group Management Interfaces</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Security-Group-Management-Interfaces/m-p/142235#M817</link>
      <description>&lt;P&gt;Don't use the management ports 1-4 if you want to route traffic through the management ports as they don't support it. Use an uplink port as management port instead. See &lt;A href="https://community.checkpoint.com/t5/Maestro/Maestro-limitation-connections-going-through-data-and-management/m-p/138595/highlight/true#M730" target="_self"&gt;here&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Feb 2022 19:34:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Security-Group-Management-Interfaces/m-p/142235#M817</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2022-02-22T19:34:32Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro Security Group Management Interfaces</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Security-Group-Management-Interfaces/m-p/142286#M818</link>
      <description>&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Wed, 23 Feb 2022 11:23:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-Security-Group-Management-Interfaces/m-p/142286#M818</guid>
      <dc:creator>Gingerwerewolf</dc:creator>
      <dc:date>2022-02-23T11:23:32Z</dc:date>
    </item>
  </channel>
</rss>

